Subscribe via feed.
Archive for April, 2019

[webapps] WordPress Plugin Limit Login Attempts Reloaded 2.7.4 – Login Limit Bypass

Posted by deepcore under Security (No Respond)

WordPress Plugin Limit Login Attempts Reloaded 2.7.4 – Login Limit Bypass

Tags: ,

[webapps] CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) – Cross-Site Scripting

Posted by deepcore under Security (No Respond)

CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) – Cross-Site Scripting

Tags: ,

[local] River Past Cam Do 3.7.6 – 'Activation Code' Local Buffer Overflow

Posted by deepcore under Security (No Respond)

River Past Cam Do 3.7.6 – ‘Activation Code’ Local Buffer Overflow

Tags: ,

[local] AllPlayer 7.4 – SEH Buffer Overflow (Unicode)

Posted by deepcore under Security (No Respond)

AllPlayer 7.4 – SEH Buffer Overflow (Unicode)

Tags: ,

Arris Touchstone TG1672 Credential Disclosure

Posted by deepcore under exploit (No Respond)

Administrative credentials submitted to the Arris Touchstone TG1672 are sent over HTTP base64 encoded in a GET request.

Open-Xchange AppSuite 7.10.1 Information Disclosure / Improper Access Control

Posted by deepcore under exploit (No Respond)

Open-Xchange AppSuite versions 7.10.1 and below suffer from information exposure and improper access control vulnerabilities.

WordPress Form Maker 1.13.2 Cross Site Request Forgery / Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Form Maker plugin version 1.13.2 suffers from cross site request forgery and local file inclusion vulnerabilities.

NC450 1.5.0 Build 181022 Rel.3A033D Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

NC450 version 1.5.0 Build 181022 Rel.3A033D contains a hardcoded root credential within its Linux distribution image.

Magic ISO Maker 5.5 Build 281 Denial Of Service

Posted by deepcore under exploit (No Respond)

Magic ISO Maker version 5.5 build 281 suffers from a denial of service vulnerability.

Lupusec XT2 Plus Main Panel Shared Secrets / Secret Disclosure / CSRF

Posted by deepcore under exploit (No Respond)

Lupusec XT2 Plus Main Panel with firmware 0l0.2.19E suffers from shared private keys for SSL certificates, root passwords derived from the MAC address, information disclosure, and cross site request forgery vulnerabilities.